Basic policy
Mitsubishi Electric India is committed to ensuring the highest standards of security across all its products and services. To strengthen this commitment, the company has established PSIRT (Product Security Incident Response Team) as an internal framework for responding to the incidents related to the information security of our products and services.
The PSIRT will be responsible for:
- Collecting and analyzing information related to potential vulnerabilities in products and services.
- Coordinating swift and effective countermeasures in collaboration with product design, manufacturing, and customer support departments.
- Transparently disclosing relevant vulnerability information and remediation measures to customers.
Mitsubishi Electric India actively promotes secure product design and development practices aimed at preventing vulnerabilities before products and services reach the customers. As part of this initiative:
- Secure development methodologies are integrated into all stages of product development.
- Comprehensive Product Security Training is conducted for all the executives and employees involved in product development and support.
Legal Compliance
We will comply with all relevant laws and regulations related to Product Security. In addition, we will take appropriate measures to protect personal information.
Vulnerability disclosure policy
Reporting
To enhance the security of our products, we actively receive and assess vulnerability information from external security researchers and established coordinating organizations, including national CERTs. Suspected vulnerabilities in our products can be reported directly to us through the vulnerability reporting form.
Investigation and countermeasures
The relevant product design and development department will review and investigate the vulnerability information provided by the reporter. If the defined evaluation criteria are met, the issue will be classified as a confirmed vulnerability, and the results of the investigation will be communicated to the reporter. Additional information may be requested as necessary during the investigation.
We will implement countermeasures and prepare to disclose a new vulnerability.
Publication of security advisory
To enable customers to take appropriate measures against identified vulnerabilities, a security advisory will be prepared and published. The publication date will be coordinated with the reporter and other relevant stakeholders once the advisory is ready for release. Following the assignment of a CVE identifier, the advisory will be published on our website.
At the same time, the vulnerability will be communicated to the NCERT and to the CERT of each country, as necessary.
Vulnerability advisory
Refer to the list below for current vulnerability disclosures. Disclosures are organized by year.
| Date YYYY/MM/DD | Product Category | Pdf File | Vulnerability Disclosure Description |
|---|